<?xml version="1.0" encoding="utf-8"?>
<!-- generator="FeedCreator 1.7.2" -->
<rss version="2.0">
    <channel>
        <title>Lowyat.NET: Latest topics by Canning</title>
        <description></description>
        <link>http://forum.lowyat.net/</link>
        <lastBuildDate>Mon, 22 Jun 2026 00:27:57 +0800</lastBuildDate>
        <generator>FeedCreator 1.7.2</generator>
        <item>
            <title>WMA/TrojanDownloader.GetCodec.gen</title>
            <link>http://forum.lowyat.net/topic/805751</link>
            <description>Logfile of HijackThis v1.99.1&lt;br /&gt;Scan saved at 4:49:28 p.m., on 1/10/2008&lt;br /&gt;Platform: Windows XP SP2 (WinNT 5.01.2600)&lt;br /&gt;MSIE: Internet Explorer v7.00 (7.00.5346.0005)&lt;br /&gt;&lt;br /&gt;Running processes:&lt;br /&gt;C:&amp;#092;WINDOWS&amp;#092;System32&amp;#092;smss.exe&lt;br /&gt;C:&amp;#092;WINDOWS&amp;#092;system32&amp;#092;winlogon.exe&lt;br /&gt;C:&amp;#092;WINDOWS&amp;#092;system32&amp;#092;services.exe&lt;br /&gt;C:&amp;#092;WINDOWS&amp;#092;system32&amp;#092;lsass.exe&lt;br /&gt;C:&amp;#092;WINDOWS&amp;#092;system32&amp;#092;Ati2evxx.exe&lt;br /&gt;C:&amp;#092;WINDOWS&amp;#092;system32&amp;#092;svchost.exe&lt;br /&gt;C:&amp;#092;WINDOWS&amp;#092;System32&amp;#092;svchost.exe&lt;br /&gt;C:&amp;#092;WINDOWS&amp;#092;system32&amp;#092;svchost.exe&lt;br /&gt;C:&amp;#092;WINDOWS&amp;#092;system32&amp;#092;spoolsv.exe&lt;br /&gt;C:&amp;#092;WINDOWS&amp;#092;system32&amp;#092;Ati2evxx.exe&lt;br /&gt;C:&amp;#092;WINDOWS&amp;#092;Explorer.EXE&lt;br /&gt;C:&amp;#092;Program Files&amp;#092;Common Files&amp;#092;Apple&amp;#092;Mobile Device Support&amp;#092;bin&amp;#092;AppleMobileDeviceService.exe&lt;br /&gt;C:&amp;#092;Program Files&amp;#092;Bonjour&amp;#092;mDNSResponder.exe&lt;br /&gt;C:&amp;#092;Program Files&amp;#092;xampp&amp;#092;FileZillaFTP&amp;#092;FileZillaServer.exe&lt;br /&gt;C:&amp;#092;Program Files&amp;#092;Common Files&amp;#092;Microsoft Shared&amp;#092;VS7DEBUG&amp;#092;MDM.EXE&lt;br /&gt;C:&amp;#092;Program Files&amp;#092;Eset&amp;#092;nod32krn.exe&lt;br /&gt;C:&amp;#092;Program Files&amp;#092;Alcohol Soft&amp;#092;Alcohol 120&amp;#092;StarWind&amp;#092;StarWindService.exe&lt;br /&gt;C:&amp;#092;WINDOWS&amp;#092;RTHDCPL.EXE&lt;br /&gt;C:&amp;#092;WINDOWS&amp;#092;System32&amp;#092;svchost.exe&lt;br /&gt;C:&amp;#092;Program Files&amp;#092;ATI Technologies&amp;#092;ATI.ACE&amp;#092;cli.exe&lt;br /&gt;C:&amp;#092;Program Files&amp;#092;iTunes&amp;#092;iTunesHelper.exe&lt;br /&gt;C:&amp;#092;WINDOWS&amp;#092;system32&amp;#092;ctfmon.exe&lt;br /&gt;C:&amp;#092;Program Files&amp;#092;InterVideo&amp;#092;Common&amp;#092;Bin&amp;#092;WinCinemaMgr.exe&lt;br /&gt;C:&amp;#092;Program Files&amp;#092;ITE&amp;#092;ITE IT8212 ATA RAID Controller&amp;#092;RaidMgr.exe&lt;br /&gt;C:&amp;#092;Program Files&amp;#092;iPod&amp;#092;bin&amp;#092;iPodService.exe&lt;br /&gt;C:&amp;#092;Program Files&amp;#092;iTunes&amp;#092;iTunes.exe&lt;br /&gt;C:&amp;#092;Program Files&amp;#092;Mozilla Firefox&amp;#092;firefox.exe&lt;br /&gt;C:&amp;#092;Program Files&amp;#092;Eset&amp;#092;nod32.exe&lt;br /&gt;C:&amp;#092;Program Files&amp;#092;Mozilla Thunderbird&amp;#092;thunderbird.exe&lt;br /&gt;C:&amp;#092;Documents and Settings&amp;#092;Paul&amp;#092;Desktop&amp;#092;HijackThis&amp;#092;HijackThis.exe&lt;br /&gt;&lt;br /&gt;R1 - HKLM&amp;#092;Software&amp;#092;Microsoft&amp;#092;Internet Explorer&amp;#092;Main,Default_Page_URL = &lt;a href='http://go.microsoft.com/fwlink/?LinkId=54729' target='_blank'&gt;http://go.microsoft.com/fwlink/?LinkId=54729&lt;/a&gt;&lt;br /&gt;R1 - HKLM&amp;#092;Software&amp;#092;Microsoft&amp;#092;Internet Explorer&amp;#092;Main,Default_Search_URL = &lt;a href='http://go.microsoft.com/fwlink/?LinkId=54896' target='_blank'&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/a&gt;&lt;br /&gt;R1 - HKLM&amp;#092;Software&amp;#092;Microsoft&amp;#092;Internet Explorer&amp;#092;Main,Search Page = &lt;a href='http://go.microsoft.com/fwlink/?LinkId=54896' target='_blank'&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/a&gt;&lt;br /&gt;R0 - HKLM&amp;#092;Software&amp;#092;Microsoft&amp;#092;Internet Explorer&amp;#092;Main,Start Page = &lt;a href='http://go.microsoft.com/fwlink/?LinkId=55245&amp;clcid={SUB_CLCID}' target='_blank'&gt;http://go.microsoft.com/fwlink/?LinkId=552...cid={SUB_CLCID}&lt;/a&gt;&lt;br /&gt;R1 - HKCU&amp;#092;Software&amp;#092;Microsoft&amp;#092;Windows&amp;#092;CurrentVersion&amp;#092;Internet Settings,ProxyServer = proxy.student.otago.ac.nz:3128&lt;br /&gt;O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)&lt;br /&gt;O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:&amp;#092;Program Files&amp;#092;Adobe&amp;#092;Acrobat 7.0&amp;#092;ActiveX&amp;#092;AcroIEHelper.dll&lt;br /&gt;O2 - BHO: IeCatch5 Class - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:&amp;#092;PROGRA~1&amp;#092;FlashGet&amp;#092;jccatch.dll&lt;br /&gt;O2 - BHO: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:&amp;#092;PROGRA~1&amp;#092;MEGAUP~1&amp;#092;MEGAUP~1.DLL&lt;br /&gt;O2 - BHO: Canon Easy Web Print Helper - {68F9551E-0411-48E4-9AAF-4BC42A6A46BE} - C:&amp;#092;Program Files&amp;#092;Canon&amp;#092;Easy-WebPrint&amp;#092;EWPBrowseLoader.dll&lt;br /&gt;O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:&amp;#092;Program Files&amp;#092;Java&amp;#092;jre1.5.0_10&amp;#092;bin&amp;#092;ssv.dll&lt;br /&gt;O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)&lt;br /&gt;O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:&amp;#092;Program Files&amp;#092;Common Files&amp;#092;Microsoft Shared&amp;#092;Windows Live&amp;#092;WindowsLiveLogin.dll&lt;br /&gt;O2 - BHO: gFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:&amp;#092;PROGRA~1&amp;#092;FlashGet&amp;#092;getflash.dll&lt;br /&gt;O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:&amp;#092;PROGRA~1&amp;#092;FlashGet&amp;#092;fgiebar.dll&lt;br /&gt;O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:&amp;#092;Program Files&amp;#092;Canon&amp;#092;Easy-WebPrint&amp;#092;Toolband.dll&lt;br /&gt;O3 - Toolbar: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:&amp;#092;PROGRA~1&amp;#092;MEGAUP~1&amp;#092;MEGAUP~1.DLL&lt;br /&gt;O4 - HKLM&amp;#092;..&amp;#092;Run: [ATIPTA] C:&amp;#092;Program Files&amp;#092;ATI Technologies&amp;#092;ATI Control Panel&amp;#092;atiptaxx.exe&lt;br /&gt;O4 - HKLM&amp;#092;..&amp;#092;Run: [nod32kui] &amp;quot;C:&amp;#092;Program Files&amp;#092;Eset&amp;#092;nod32kui.exe&amp;quot; /WAITSERVICE&lt;br /&gt;O4 - HKLM&amp;#092;..&amp;#092;Run: [RTHDCPL] RTHDCPL.EXE&lt;br /&gt;O4 - HKLM&amp;#092;..&amp;#092;Run: [Alcmtr] ALCMTR.EXE&lt;br /&gt;O4 - HKLM&amp;#092;..&amp;#092;Run: [ATICCC] &amp;quot;C:&amp;#092;Program Files&amp;#092;ATI Technologies&amp;#092;ATI.ACE&amp;#092;cli.exe&amp;quot; runtime -Delay&lt;br /&gt;O4 - HKLM&amp;#092;..&amp;#092;Run: [NeroFilterCheck] C:&amp;#092;WINDOWS&amp;#092;system32&amp;#092;NeroCheck.exe&lt;br /&gt;O4 - HKLM&amp;#092;..&amp;#092;Run: [WinampAgent] &amp;quot;C:&amp;#092;Program Files&amp;#092;Winamp&amp;#092;winampa.exe&amp;quot;&lt;br /&gt;O4 - HKLM&amp;#092;..&amp;#092;Run: [snpstd] C:&amp;#092;WINDOWS&amp;#092;vsnpstd.exe&lt;br /&gt;O4 - HKLM&amp;#092;..&amp;#092;Run: [AppleSyncNotifier] C:&amp;#092;Program Files&amp;#092;Common Files&amp;#092;Apple&amp;#092;Mobile Device Support&amp;#092;bin&amp;#092;AppleSyncNotifier.exe&lt;br /&gt;O4 - HKLM&amp;#092;..&amp;#092;Run: [QuickTime Task] &amp;quot;C:&amp;#092;Program Files&amp;#092;QuickTime&amp;#092;QTTask.exe&amp;quot; -atboottime&lt;br /&gt;O4 - HKLM&amp;#092;..&amp;#092;Run: [iTunesHelper] &amp;quot;C:&amp;#092;Program Files&amp;#092;iTunes&amp;#092;iTunesHelper.exe&amp;quot;&lt;br /&gt;O4 - HKCU&amp;#092;..&amp;#092;Run: [ctfmon.exe] C:&amp;#092;WINDOWS&amp;#092;system32&amp;#092;ctfmon.exe&lt;br /&gt;O4 - HKCU&amp;#092;..&amp;#092;Run: [StartCCC] C:&amp;#092;Program Files&amp;#092;ATI Technologies&amp;#092;ATI.ACE&amp;#092;Core-Static&amp;#092;CLIStart.exe&lt;br /&gt;O4 - HKCU&amp;#092;..&amp;#092;Run: [proc dead] C:&amp;#092;DOCUME~1&amp;#092;Paul&amp;#092;APPLIC~1&amp;#092;SAFEDA~1&amp;#092;FindBoobProgram.exe&lt;br /&gt;O4 - HKCU&amp;#092;..&amp;#092;Run: [updateMgr] &amp;quot;C:&amp;#092;Program Files&amp;#092;Adobe&amp;#092;Acrobat 7.0&amp;#092;Reader&amp;#092;AdobeUpdateManager.exe&amp;quot; AcRdB7_0_9 -reboot 1&lt;br /&gt;O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:&amp;#092;Program Files&amp;#092;Adobe&amp;#092;Acrobat 7.0&amp;#092;Reader&amp;#092;reader_sl.exe&lt;br /&gt;O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:&amp;#092;Program Files&amp;#092;InterVideo&amp;#092;Common&amp;#092;Bin&amp;#092;WinCinemaMgr.exe&lt;br /&gt;O4 - Global Startup: QuickBooks Update Agent.lnk = C:&amp;#092;Program Files&amp;#092;Common Files&amp;#092;Intuit&amp;#092;QuickBooks&amp;#092;QBUpdate&amp;#092;qbupdate.exe&lt;br /&gt;O4 - Global Startup: RAID Manager.lnk = C:&amp;#092;Program Files&amp;#092;ITE&amp;#092;ITE IT8212 ATA RAID Controller&amp;#092;RaidMgr.exe&lt;br /&gt;O8 - Extra context menu item: Download All by FlashGet - C:&amp;#092;Program Files&amp;#092;FlashGet&amp;#092;jc_all.htm&lt;br /&gt;O8 - Extra context menu item: Download using FlashGet - C:&amp;#092;Program Files&amp;#092;FlashGet&amp;#092;jc_link.htm&lt;br /&gt;O8 - Extra context menu item: E&amp;amp;xport to Microsoft Excel - res://C:&amp;#092;PROGRA~1&amp;#092;MICROS~2&amp;#092;OFFICE11&amp;#092;EXCEL.EXE/3000&lt;br /&gt;O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:&amp;#092;Program Files&amp;#092;Canon&amp;#092;Easy-WebPrint&amp;#092;Toolband.dll/RC_AddToList.html&lt;br /&gt;O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:&amp;#092;Program Files&amp;#092;Canon&amp;#092;Easy-WebPrint&amp;#092;Toolband.dll/RC_HSPrint.html&lt;br /&gt;O8 - Extra context menu item: Easy-WebPrint Preview - res://C:&amp;#092;Program Files&amp;#092;Canon&amp;#092;Easy-WebPrint&amp;#092;Toolband.dll/RC_Preview.html&lt;br /&gt;O8 - Extra context menu item: Easy-WebPrint Print - res://C:&amp;#092;Program Files&amp;#092;Canon&amp;#092;Easy-WebPrint&amp;#092;Toolband.dll/RC_Print.html&lt;br /&gt;O8 - Extra context menu item: Open using &amp;amp;Advanced JPEG Compressor - C:&amp;#092;Program Files&amp;#092;Advanced JPEG Compressor&amp;#092;ajcieex.htm&lt;br /&gt;O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:&amp;#092;Program Files&amp;#092;Java&amp;#092;jre1.5.0_10&amp;#092;bin&amp;#092;ssv.dll&lt;br /&gt;O9 - Extra &amp;#39;Tools&amp;#39; menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:&amp;#092;Program Files&amp;#092;Java&amp;#092;jre1.5.0_10&amp;#092;bin&amp;#092;ssv.dll&lt;br /&gt;O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:&amp;#092;PROGRA~1&amp;#092;MICROS~2&amp;#092;OFFICE11&amp;#092;REFIEBAR.DLL&lt;br /&gt;O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:&amp;#092;PROGRA~1&amp;#092;FlashGet&amp;#092;flashget.exe&lt;br /&gt;O9 - Extra &amp;#39;Tools&amp;#39; menuitem: &amp;amp;FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:&amp;#092;PROGRA~1&amp;#092;FlashGet&amp;#092;flashget.exe&lt;br /&gt;O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:&amp;#092;Program Files&amp;#092;Messenger&amp;#092;msmsgs.exe&lt;br /&gt;O9 - Extra &amp;#39;Tools&amp;#39; menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:&amp;#092;Program Files&amp;#092;Messenger&amp;#092;msmsgs.exe&lt;br /&gt;O10 - Unknown file in Winsock LSP: c:&amp;#092;program files&amp;#092;bonjour&amp;#092;mdnsnsp.dll&lt;br /&gt;O11 - Options group: [INTERNATIONAL] International*&lt;br /&gt;O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - &lt;a href='http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1177141510171' target='_blank'&gt;http://update.microsoft.com/windowsupdate/...b?1177141510171&lt;/a&gt;&lt;br /&gt;O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - &lt;a href='http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab' target='_blank'&gt;http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab&lt;/a&gt;&lt;br /&gt;O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) - &lt;a href='http://www.sibelius.com/download/software/win/ActiveXPlugin.cab' target='_blank'&gt;http://www.sibelius.com/download/software/...tiveXPlugin.cab&lt;/a&gt;&lt;br /&gt;O16 - DPF: {BD08A9D5-0E5C-4F42-99A3-C0CB5E860557} (CSolidBrowserObj Object) - &lt;a href='http://www.solidstatenetworks.com/demos/plugin/solidstateion.cab' target='_blank'&gt;http://www.solidstatenetworks.com/demos/pl...lidstateion.cab&lt;/a&gt;&lt;br /&gt;O16 - DPF: {BE30D547-EE96-4D6B-B9A3-57777E9F0A9C} (ActiveFormX Element) - &lt;a href='http://127.0.0.1:9191/nnvbibnc/activex/common/bin/go1984Viewer.ocx' target='_blank'&gt;http://127.0.0.1:9191/nnvbibnc/activex/com...o1984Viewer.ocx&lt;/a&gt;&lt;br /&gt;O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - &lt;a href='http://messenger.zone.msn.com/binary/SolitaireShowdown.cab31267.cab' target='_blank'&gt;http://messenger.zone.msn.com/binary/Solit...wn.cab31267.cab&lt;/a&gt;&lt;br /&gt;O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:&amp;#092;PROGRA~1&amp;#092;WI1F86~1&amp;#092;MESSEN~1&amp;#092;MSGRAP~1.DLL&lt;br /&gt;O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:&amp;#092;PROGRA~1&amp;#092;WI1F86~1&amp;#092;MESSEN~1&amp;#092;MSGRAP~1.DLL&lt;br /&gt;O20 - Winlogon Notify: WgaLogon - C:&amp;#092;WINDOWS&amp;#092;SYSTEM32&amp;#092;WgaLogon.dll&lt;br /&gt;O20 - Winlogon Notify: winzoa32 - C:&amp;#092;WINDOWS&amp;#092;SYSTEM32&amp;#092;winzoa32.dll&lt;br /&gt;O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:&amp;#092;WINDOWS&amp;#092;system32&amp;#092;WPDShServiceObj.dll&lt;br /&gt;O23 - Service: Apple Mobile Device - Apple Inc. - C:&amp;#092;Program Files&amp;#092;Common Files&amp;#092;Apple&amp;#092;Mobile Device Support&amp;#092;bin&amp;#092;AppleMobileDeviceService.exe&lt;br /&gt;O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:&amp;#092;WINDOWS&amp;#092;system32&amp;#092;Ati2evxx.exe&lt;br /&gt;O23 - Service: ATI Smart - Unknown owner - C:&amp;#092;WINDOWS&amp;#092;system32&amp;#092;ati2sgag.exe&lt;br /&gt;O23 - Service: Bonjour Service - Apple Inc. - C:&amp;#092;Program Files&amp;#092;Bonjour&amp;#092;mDNSResponder.exe&lt;br /&gt;O23 - Service: FileZilla Server FTP server (FileZilla Server) - FileZilla Project - C:&amp;#092;Program Files&amp;#092;xampp&amp;#092;FileZillaFTP&amp;#092;FileZillaServer.exe&lt;br /&gt;O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:&amp;#092;Program Files&amp;#092;Common Files&amp;#092;InstallShield&amp;#092;Driver&amp;#092;11&amp;#092;Intel 32&amp;#092;IDriverT.exe&lt;br /&gt;O23 - Service: iPod Service - Apple Inc. - C:&amp;#092;Program Files&amp;#092;iPod&amp;#092;bin&amp;#092;iPodService.exe&lt;br /&gt;O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset  - C:&amp;#092;Program Files&amp;#092;Eset&amp;#092;nod32krn.exe&lt;br /&gt;O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:&amp;#092;Program Files&amp;#092;Alcohol Soft&amp;#092;Alcohol 120&amp;#092;StarWind&amp;#092;StarWindService.exe&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;My current virus scanner is NOD32, and everytime I go to play any of my music in iTunes, 1) it wont play and 2) NOD32 detects the WMA/TrojanDownloader.GetCodec.gen trojan and wants to delete the file. Can anyone help me remove the virus without deleting all of my music? I really don&amp;#39;t want to lose all 70gb of it&amp;#33;&amp;#33;&lt;br /&gt;&lt;br /&gt;Thanks&amp;#33;</description>
            <author>Canning</author>
            <category>Technical Support</category>
            <pubDate>Wed, 01 Oct 2008 11:54:04 +0800</pubDate>
        </item>
    </channel>
</rss>
